Skip to main content
CybersecurityIncident Response

CISA's CDM Program Accelerates Federal Cybersecurity Push

CISA's CDM Program Accelerates Federal Cybersecurity Push

"We have to get faster," said Richard Grabowski, acting branch chief of service delivery and deputy program manager for the Continuous Diagnostics and Mitigation program at CISA, summing up a blunt prescription for how the agency intends to change the way it equips other federal entities to defend themselves.

Richard Grabowski: velocity, unification, and data-driven risk management

At the Elastic Federal Cyber Defense Breakfast, produced by FedScoop, Grabowski laid out three core goals for CISA's Continuous Diagnostics and Mitigation (CDM) program: velocity, unification and data-driven risk management. On velocity he warned plainly that current collaboration models are too slow: "The way that we collaborated today wasn’t fast enough for the threats of yesterday, and they certainly aren’t going to be fast enough for the threats of tomorrow." He argued this requires responsible automation at scale so human experts can focus on "dealing with the novel threats and adoption and tuning of advanced technology, and not hitting alerts every other day."

On unification, Grabowski said the program must keep data out of silos and "connect those deployments in a meaningful way to really stimulate reusable, actionable lessons learned." For data-driven risk management, he said agencies must be able, in a crisis-level event, to "see what is happening with timely, accurate, and trustworthy data, so that we are the tool of first response when the things hit the fan."

SIEM as a Service and the three-year roadmap

One of CDM’s concrete offerings is Security Information and Event Management (SIEM) as a Service — described in the briefing as a cloud-based platform for threat analytics, incident response and more. Grabowski said CDM has a three-year roadmap to expand and enhance that capability, and that the plan includes ramping up staff and conducting training to support the service's wider adoption.

Mike Duffy’s three principles for CDM’s next phase

Mike Duffy, the acting federal chief information security officer, set out three principles he said should guide the program's evolution. First: aggregate demand across agencies that share common problems, so "when agencies need the same capabilities, we should use federal scale to improve security, interoperability and value." Second: buy outcomes rather than specific products — "making it clear what outcomes the federal government is seeking and then allowing commercial markets room to innovate." Third: design acquisition for continuous improvement so procurement models "promote competition and opportunities for new capabilities to enter."

Duffy cautioned against locking capabilities in for long periods: "Now is not the time to set capabilities and move on for the next 10 years," he said, urging an "agile mindset" to keep delivering and deploying capabilities matched to observed threats.

Post-SolarWinds: why a common operating picture matters

Matt House, CISA’s acting associate director and program manager for CDM, tied the program’s evolution to lessons from the SolarWinds breach. House said that breach, which the source describes as having "compromised at least nine federal agencies," exposed a government-wide deficit: a lack of a "common operating picture with respect to the operational visibility we need to be able to assess and coordinate response government wide." That gap underpins the program's push for unified data and the emphasis on tools that allow coordinated, timely response during large incidents.

What this means for technologists, procurement leaders, and federal agencies

  • Technologists and security teams: Expect an emphasis on automation at scale and reduced alert fatigue so staff can spend more time on novel threats, per Grabowski’s comments about shifting human attention toward tuning advanced technology.
  • Procurement leaders: Duffy’s guidance to "buy outcomes, not product" and to "design acquisition for continuous improvement" signals a shift toward outcome-based contracting, federal-scale aggregation of demand, and procurement processes that keep doors open for new entrants.
  • Federal agencies: Agencies are being asked to move toward platforms that share timely, accurate, trustworthy data so they can be part of a coordinated, government-wide response — a capability leaders say was insufficient after SolarWinds.

CISA officials are explicit about the work ahead: accelerate collaboration, unify data flows to break down silos, and realign acquisitions so capabilities can continuously evolve. Concrete steps mentioned at the event include a three-year SIEM-as-a-Service roadmap, increased staffing, and training to support broader, faster adoption. The agency framed those steps as necessary not only to keep pace with past threats but to prepare for those it expects next.

Read the original CyberScoop story